Menu

#3 sql injection vulnerabilities

open
nobody
None
5
2012-05-07
2012-05-07
No

There is a sql injection vulnerability in the url when it parses a get variable because it doesn't validate that variable's type and doesn't escape the string
There's also a similar post vulnerability.

Both are described here:
http://packetstormsecurity.org/files/111868/VL-503.txt

Discussion


Log in to post a comment.

MongoDB Logo MongoDB